The Board Room
Anthropic's Mythos became the first AI model to fully take over both UK AISI attack
Patch SLAs and endpoint detection assumptions were calibrated for human-speed adversaries. The honest question is not whether defenders have twelve to eighteen months before this proliferates. It is whether the rebuild started last quarter or has not started.
AI Cyber Offense Crosses Full Autonomy Threshold
Mythos cleared both AISI simulated attack ranges (first model ever). TrustedSec proved all five major EDRs share identical architectures now transparent to AI. PraisonAI was exploited within 4 hours of disclosure. NSA — not CISA — is getting access. The defensive model just broke.
AI Infrastructure Enters Public-Market Validation Phase
Cerebras IPO at $56B (+70% day one) on a $20B OpenAI anchor contract. Fervo Energy surged 33% at $10B+ driven by Google's 3GW option. Microsoft's total OpenAI commitment disclosed at $100B+. xAI leasing 45% of Colossus to Anthropic signals compute is financializing. The window to secure favorable multi-year capacity is closing.
Agent Platform War: Who Controls the Execution Layer
SAP (€100M fund, Knowledge Graph) and ServiceNow (headless Action Fabric via MCP) collide on who owns agent writes to enterprise systems of record. Apple is building agent gatekeeping into the App Store. Google's Gemini Intelligence ships on Android this summer. Vercel confirms 59% of AI traffic is now agentic. The execution layer is the new platform control point.
AI Liability Architecture Under Active Construction
a16z published the industry's definitive liability framework advocating user-liability defaults and damages caps. Courts are simultaneously deciding precedent-setting cases. ODNI and Commerce are fighting over pre-release model evaluation authority. The outcome determines whether open-source AI remains viable and whether incumbents or challengers survive.
Your Security Model Just Broke on Two Axes — EDR Transparency + Autonomous Offense
The Capability Discontinuity
The week produced a convergence that calls for an architectural response rather than a budget one. Anthropic's Mythos became the first model to clear both UK AISI simulated attack ranges, achieving full autonomous network takeover rather than persistence or lateral movement alone. OpenAI's GPT-5.5-cyber cleared one of the two. Across multiple independent assessments, researcher consensus is now that frontier models can find, chain, and exploit vulnerabilities in something close to real time.
In the same week, TrustedSec ran LLMs against five commercial EDR products and found all five share identical architectural patterns: YARA-style rules, behavioral logic, allowlists, prefilters, scripted engines readable as Lua after a single decryption pass, and local ML classifiers. Work that took a skilled reverse engineer weeks now finishes in days. The EDR category's defensive moat was security-through-obscurity. The obscurity has left the building.
The security model was built on the premise that the cost of understanding the agent exceeded the value of bypassing it for most adversaries. That premise is no longer true for a growing share of the threat population.
The Evidence Stack
- Mythos: first model to clear both AISI end-to-end cyber ranges
- PraisonAI: exploited within 4 hours of disclosure, well below most patch SLAs
- LiteLLM, Ollama, OpenClaw: added to CISA KEV. AI infrastructure is being exploited in the wild now
- LLMjacking honeypot: 113,000+ attacks per month, tooling maturing mid-experiment
- NGINX: 18-year undetected RCE in the rewrite module, foundational infrastructure that "many eyes" missed
- Foxconn: 8TB of Apple, Google, Intel, and Nvidia designs exfiltrated via Nitrogen ransomware
Where Sources Disagree, And Why It Matters
A tension runs through today's intelligence. The research community sees a 12-18 month window before these capabilities proliferate to open-weight models and the long tail of threat actors. The policy signals suggest otherwise. Congress is routing Mythos access through NSA, not CISA, which prioritizes offensive and intelligence operations over civilian defense. The private sector is on its own for that window.
A reasonable skeptic would note that AI-powered defensive scanning is equally transformative. Mozilla found 271 bugs in Firefox; Microsoft's MDASH surfaced 16 exploitable flaws in a single patch cycle. The skeptic is correct, with one caveat: the key variable is harness design, not model selection. Mozilla's 271 bugs came from custom agentic harnesses, while generic scanning of curl produced one low-severity CVE. The moat is in orchestration.
The Architectural Consequence
Security architecture built around quarterly patching, annual pentests, and endpoint-as-load-bearing-control was calibrated for human-speed adversaries. That calibration is now wrong. The compensating controls that matter in the next eighteen months sit above the endpoint: identity, network telemetry, behavioral analytics. Patch SLAs written for a 30-day window need rewriting for a 7-day window on the exposures that actually matter.
AI cyber offense achieved full autonomous network takeover this week while a parallel study proved every major endpoint security product is now transparent to AI — and the infrastructure to defend against it is being pre-sold in $20 billion blocks to buyers who aren't you. The two decisions that compress into this quarter: rebuild your security architecture for machine-speed adversaries before the capability proliferates in 12-18 months, and source compute capacity through multi-year commitments before the remaining supply gets locked into bilateral deals between hyperscalers. Everything else — the platform wars, the liability regime, the org model — matters on a two-year clock. These two matter now.